- Effect: Allow
Action:
- sqs:GetQueueAttributes
- sqs:ListQueues
- sqs:ReceiveMessage
- sqs:GetQueueUrl
- sqs:SendMessage
- sqs:DeleteMessage
- s3:ListBucket
- s3:GetBucketLocation
- s3:ListAllMyBuckets
- config:DeliverConfigSnapshot
- config:DescribeConfigRules
- config:DescribeDeliveryChannels
- config:DescribeConfigRuleEvaluationStatus
- config:GetComplianceDetailsByConfigRule
- config:GetComplianceSummaryByConfigRule
- iam:GetUser
- autoscaling:Describe*
- cloudwatch:Describe*
- cloudwatch:Get*
- cloudwatch:List*
- sns:Get*
- sns:List*
- sns:Publish
- logs:DescribeLogGroups
- logs:DescribeLogStreams
- logs:GetLogEvents
- ec2:DescribeInstances
- ec2:DescribeReservedInstances
- ec2:DescribeSnapshots
- ec2:DescribeRegions
- ec2:DescribeKeyPairs
- ec2:DescribeNetworkAcls
- ec2:DescribeSecurityGroups
- ec2:DescribeSubnets
- ec2:DescribeVolumes
- ec2:DescribeVpcs
- ec2:DescribeImages
- ec2:DescribeAddresses
- lambda:List*
- rds:DescribeDBInstances
- cloudfront:ListDistributions
- elasticloadbalancing:DescribeLoadBalancers
- elasticloadbalancing:DescribeInstanceHealth
- inspector:Describe*
- inspector:List*
- kinesis:Get*
- kinesis:Describe*
- kinesis:List*
- lambda:List*
- cloudfront:Get*
- cloudtrail:DescribeTrails
Resource: "*"
Users:
- Ref: IAMUser
Splunk IAM User CloudFormation Deployment
This CloudFormation template will deploy an IAM User with permissions Splunk needs.